CVE-2024-37103

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-37103 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Education Zone component of Rara Theme. This issue permits malicious actors to trick users into performing unintended actions on the affected system, potentially leading to data theft or unauthorized modifications. The vulnerability can be exploited by sending specially crafted requests to the user's browser, which, if successful, can result in the execution of malicious commands on the Education Zone platform. This vulnerability can impact Education Zone installations ranging from version n/a through 1.3.4, emphasizing the importance of prompt patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share